Threat Modeling: An Introduction

I have previously written about categorizing attackers based on their levels of skill and focus. I have also written about categorizing security measures to defeat attackers with a given level of skill or focus. Both of these posts tie in closely with (and were early attempts at) a topic that I want to explore more fully in coming months: threat modeling.

Attacks and Attackers, Categorized

In previous posts I have referenced two different types of attacks: opportunistic and focused. These categories apply to attacks of all kinds, physical and digital, an understanding them is important to fully understanding how to defend against them. This post will attempt to categorize these two types of attack and the attackers that may carry out each.

